Very strange stuff going on

Discussion in 'Malware Help (A Specialist Will Reply)' started by ducati, Dec 12, 2006.

  1. ducati

    ducati Private E-2

    Ok, well stuff is getting even weirder now. I have run all the steps, did not get any virus/trojan hits, very few spyware. When I startup my computer, doesnt matter if its in safe mode or not, it opens up "my documents" and thats it, no start menu, no trays, no desktop items, nothing else. I have no idea what to think.
     

    Attached Files:

  2. ducati

    ducati Private E-2

    here is the other files
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you experimenting on your own deleting things? Did you use HijackThis to fix anything on your own?

    You seem to have deleted the registry entries to load your system shell. The shell is explorer.exe

    Check a couple things
    1. Press CTRL-SHIFT-ESC to bring up Task Manager
    2. Click File, New Task (Run...) and enter explorer.exe and click OK
    3. Does your Desktop (icons...etc) appear
    4. if not, you may have deleted the explorer.exe file.
    5. Click File, New Task (Run...) and enter cmd and click OK
    6. A command prompt should open. Enter cd c:\windows in the command prompt window and hit enter
    7. then enter dir explorer.exe and hit enter. Tell me if it lists the explorer.exe file.
    Are you sure you extracted all of the files from the GetRunKey.zip file like you did for ShowNew. It does not look like it based on the error messages in the log.
     
  4. ducati

    ducati Private E-2

    When windows starts it opens up the my documents folder automatically. When I type in the explorer.exe into the prompt, it does the same thing, the icons are not there, and the toolbar isnt at the bottom. I have not done any editing of my registry files, the only thing i really have messed with is msconfig to control what starts up, but ive been doing that for a very long time. Also, when i run hjt, should i select the fix problems button? I wasnt sure on this because i tried very hard to follow the directions as closely as possible. I did the get run zip the same way i did the show new, but i will try it again and post the results in the next reply. maybe i did it wrong tho, what im doing is right clicking on the zip and hitting explore, then i click on the .bat file, which prompts me to "extract all", "run", or "cancel". I then extract that to its own folder, is this correct. oh yea, the dos that you had me run does list explorer in windows.
     
  5. ducati

    ducati Private E-2

    one more thing, i had to go into normal startup rather than the safe mode with networking to run the online scanners
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to type explorer at the command prompt. I asked you to enter it in the Task Manager New Task (Run...) box. Is that what you meant?

    Like what?

    HijackThis does not have a "fix problems" button. HijackThis is not a malware scanning tool. It does not make any references nor does is it detect whether something is bad or good. It only shows a list of running processes and dumps a list a various registry keys. It is up to the VERY educated user to know what to do with this information and to decide whether it is normal (good) or not normal (bad). It you do the wrong thing with HJT, you can make your PC unusable. Don't do anything with it on your own.

    You have to extract ALL files. And then you must run GetRunKey.bat from a Windows Explorer prompt but since you cannot run Windows Explorer how are you doing this? How are you seeing the ZIP files at all? What program are you running that is locating the files? How are you getting the window/process started? Are you just using the My Documents window that opens at startup to navigate around? Copy or move the GetRunKey.bat (only copy it) into the same folder as ShowNew.bat. Then attach new logs from GetRunKey and Shownew.


    Tell me the exact information listed for explorer.exe (like file size and date).


    On Dec 5th you downloaded ie6setup.exe to your Desktop! Did you only just recently upgrade to IE6? When did your problems start? Before or after running this?


    I also see LimeWire was installed on Dec 10 th? When did your problems start? Before or after running this?

    What I'm trying to find out is exactly when your problems with no Desktop appearing began! Was this the reason you started running the READ & RUN ME? Or did you have malware problems and then started running the READ & RUN ME and while running the steps your Desktop went away. Part of the reason, I'm asking this is because your logs show now malware so I'm wondering what was the reason for running the READ ME. Right now I'm guessing it was because of your Desktop issue which does not appear to be caused by malware.

    I also want you to go to the below site and scan your explorer.exe file. Use the Browse button on the web page and then navigate to your c:\windows folder and choose the explorer.exe file. Attach the results (copy and paste is okay).

    http://virusscan.jotti.org/


    Now Shutdown all browsers. Also shutdown CounterSpy and as much of your McAfee software as possible. Then run HijackThis


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    After reboot attach a new HJT log. Any change to your problem? If not, continue on to the below:

    Press CTRL-SHIFT-ESC to bring up Task Manager. And click File, New Task (Run..) and enter regedit and click OK. This will run the registry editor. Now look for the below registry keys (navigate thru the registry). Make sure you only look for and delete the exact keys listed below.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplorer.exe

    After deleting this keys the desktop and explorer.exe should reappear. You may need to reboot after doing this. Let me know the results.
     
    Last edited: Dec 12, 2006
  7. ducati

    ducati Private E-2

    Alright...
    -yes i did run the explorer.exe from task manager.
    -The msconfig things i have messed with in the past are things like aim or yahoo messenger, just stuff that i know what it is and would like for it not to start up with everything else.
    -the hjt button i was refering to was the "fix checked" button, but like i said in the last post, i did not do anything because i did not want to mess anything up any further
    -I am running everything straight from the my documents folder that opens up when windows starts up. As far as my desktop not appearing, i should clarify that my background image is there, but that is it, and you can not right click or anything like that.
    - In the cmd this is what appears...
    c:\WINDOWS>dir explorer.exe
    Volume in drive C is PRESARIO
    Volume Serial Number is 60FE-1AD6
    Directory of C:\WINDOWS

    8/03/2004 11:00 PM 1,032,192 explorer.exe
    1 File(s) 1,032,192 bytes
    0 Dir(s) 128,707,166,208 bytes free

    -The reason for the ie6 download on that date was because i upgraded to ie7, and did not like it whatsoever, so i uninstalled it, and then downloaded ie6 again.
    -Limewire was re downloaded on that date because i accidently un installed it the previous day

    -The reason I came to this website, was because I was having problems with yahoo and myspace loading up in ie. The problem was that when i went to mail.yahoo.com, it would not load up at all. myspace would load, but some images would not load( like friends pictures), but on my computer downstairs, they appear just fine, same thing with the mail.yahoo. That is when i knew something was going on with ie. I do have the mcafee package for this year, keep it updated and all that, and also keep windows updated.
    -Another thing that was going on previously to the desktop going away was that when I shutdown, this message comes up, every time..

    "winlogon.exe Application Error
    This exception Single Step
    A Single step or trace operation has just been completed
    0x80004 occurred in application at location0x77a40...
    click ok to terminate, click cancel to debug"
    -also i get this message, which i have to repeatably click to make it go
    away, and thus have the machine go off
    can not load dll
    ProcNICs.dll

    That is everything that was going on prior to starting the malware removals. I was not sure why this was going on, that is why i went ahead and went thru all of the steps, if i did have malware on my computer, it was deleted before i ran any of the tests requested in the "read me". I was running the tests to try to fix the other problems, the desktop problem came up after that, which further confuses me.

    Thanks for the help, im going to get started on what you are having me do next and will attach the appropriate files in the next post.
     
  8. ducati

    ducati Private E-2

    Here is the new .txt's. let me know if i did it right this time
     

    Attached Files:

  9. ducati

    ducati Private E-2

    File: explorer.exe
    Status:
    OK(Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)

    AntiVir
    Found nothing
    ArcaVir
    Found nothing
    Avast
    Found nothing
    AVG Antivirus
    Found nothing
    BitDefender
    Found nothing
    ClamAV
    Found nothing
    Dr.Web
    Found nothing
    F-Prot Antivirus
    Found nothing
    F-Secure Anti-Virus
    Found nothing
    Fortinet
    Found nothing
    Kaspersky Anti-Virus
    Found nothing
    NOD32
    Found nothing
    Norman Virus Control
    Found nothing
    VirusBuster
    Found nothing
    VBA32
    Found nothing
     
  10. ducati

    ducati Private E-2

    Ok, doing that with HJT did work, my desktop is back. I did get a pop up notice from counter spy(i think) saying "a winlogon shell startup program requires approval... A program trying to enable itself to startup when Windows loads has been detected...Name: explorer.exe... Advice: since it is not known if this is spyware you should analyze it before deciding to allow it." then asks me to allow or block it, my question is what to do. Thank you so much for the help with everything else! So far i have not run into any problems
     
  11. ducati

    ducati Private E-2

    Oh yea, with the hjt log that you requested now that i have rebooted, do you want me to turn everything off again before running it? im pretty sure you will want me to, just double checking
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to allow explorer.exe to run. It is part of your Windows OS and if you block it, you will have the same problem again.


    Just attach a new HJT log. You don't need to shutdown anything.

    So if everything working OK now?
     
  13. ducati

    ducati Private E-2

    so far all ive noticed that doesnt work is the myspace website. when i enter it into firefox, it says at the bottom, "connecting to x.myspace.com...", i dont know if that means anything or not, either way it takes a very long time to load, and then when it does, the site barely resembles what it should be, everything is out of place, and many images dont load at all. One other thing that isnt working properly, when i startup i never see the welcome screen where you should pick the user to use and enter the pw. I actually have it set up so that you have to type the user in, but it still doesnt come up.

    I ran hjt and have attached the log.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why does it say x.myspace.com? Shouldn't it be myspace.com? Are you entering this into the address bar or are you clicking a saved Favorite. What happens when you use IE instead of FireFox?

    Run the below steps!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the XPLogin fix program given in the below link:

    http://www.dougknox.com/xp/scripts_desc/fix_xp_logon.htm
     
    Last edited: Dec 13, 2006
  15. ducati

    ducati Private E-2

    alright, i did the fix me register merge, and it was successful, and the link said that my msgina was fine, but when i restarted, I still didnt get the log on screen. And when i went to restart, I still am getting those 2 messages on the shutdown phase, the winlogon application error and the dll load error.

    As far as the myspace thing, I am typing it right into the address bar in firefox, and get that x.myspace. When i do it thru ie, it does load up, and looks pretty good, but I can not see all of my friends avatars. Its not that big of a deal if i dont, i just want to make sure there arent any security issues i am exposed to since this issue is not happening on my other computer.
     
  16. ducati

    ducati Private E-2

    Another thing i found, when i mail things thru yahoo, i can not use the address book, it does not auto complete, and when i hit the insert address, the pop up that comes up doesnt load. But, when i get emails from people from my address book, they come up as who they are. not sure if thats anything i did or not?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Did the above steps change any of your status with web pages?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  19. ducati

    ducati Private E-2

    alright, i did all of that, still having the problems tho. Myspace is now looking better thru firefox, but wont load the icons still, and still has that x.myspace thing going on, it wont load those same icons in ie either. When i turned off the computer, i am still getting the winlogon error. just now when i turned it on, i got a message saying that awgina.dll failed to load, so i went into safe mode and ran that fixer again, and it allowed me to get into here in normal mode, but i am still not getting the user screen.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears to me that your remaining problems may not be malware related but rather more like due to something broken in your Windows installation (especially for the missing Windows Welcome screen and the shutdown problems). You may need to start working this in the Software Forum. However have you checked to make sure your c:\windows\system32\awgina.dll file is not missing?

    For FireFox,
    • Re-download from this link: Mozilla FireFox
    • Now I suggest backing up your Favorites and uninstalling FireFox.
    • Then reboot (don't skip this)
    • then after reboot delete the C:\Program Files\Mozilla Firefox folder
    • Now install FireFox from the just downloaded file
    • Restore your Favorites
    Check for any problems?
     
  21. ducati

    ducati Private E-2

    sorry, i had to go out of the country, i am still experiencing the same problems, and looked for awgina.dll, it is not there. The winlogon fixer program only checked for msgina though, is that what it was supposed to do? I will wait for your reply about the missing dll before i do anything with firefox. Thanks
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! My mistake. You should not have this. Make sure that C:\WINDOWS\system32\msgina.dll exists.

    Please apply the below registry patch and then reboot and let me know what happens now.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
    Last edited: Dec 19, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds